Law / United States /
Michigan
Identity Theft Protection Act, personal information and personal identifying information defined
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 April 2011.
A breach notification rule binding public and private bodies.
As of 28 August 2026.
What it requires
- Do not assume Michigan's broader "personal identifying information" term (MCL 445.63(q)), which includes biometrics, is the breach-notice trigger. The trigger is the narrower "personal information" term (MCL 445.63(r)), which excludes biometrics.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
MCL 445.63 defines two distinct terms that must not be conflated. "Personal information," MCL 445.63(r), is a name combined with a Social Security number, driver's license or state ID number, or financial account or card number with an access code; it does not include biometric data.
"Personal identifying information," MCL 445.63(q), is a broader term, used for the Act's identity-theft-prevention and criminal provisions elsewhere in the chapter, that does include biometrics among many other data elements such as address, employer, government passport number, and account passwords. Only the narrower "personal information" term is the breach-notice trigger at MCL 445.72.
When LexLint raises it
processes_biometrics
Read the law
official Michigan Compiled Laws text, Michigan Legislature
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.